Jump to content

"Error: Access denied."


gonsoz42

Recommended Posts

Dear Moderators!

in these days, my uTorrent client starts to download some files (not all), but stops at 0.2 or 0.3 %, and displays in the status field: "Error: Access denied."

here are my processes, what was running while the error bash in:

processes.jpg

full picture: http://anouk.fpn.hu/kepek/processes.jpg

please help me, because this is very annoying.. and my only idea was the nod32 and the Comodo firewall.. but i did shut down both, and the situation doesn't changed :P

thx in advance!

Link to comment
Share on other sites

here it is:

Logfile of HijackThis v1.97.7

Scan saved at 19:22:56, on 2007. 12. 09.

Platform: Unknown Windows (WinNT 5.02.3790 SP2)

MSIE: Internet Explorer v7.00 (7.00.6000.16544)

Running processes:

C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe

C:\WINDOWS\SysWOW64\ctfmon.exe

C:\Program Files (x86)\ASUS\GamerOSD\GamerOSD.exe

C:\Program Files (x86)\Java\jre1.6.0_03\bin\jusched.exe

C:\WINDOWS\system32\CTHELPER.EXE

C:\Program Files (x86)\eMule\emule.exe

C:\Program Files (x86)\DAEMON Tools\daemon.exe

C:\Program Files (x86)\Hide IP Platinum\hideippla.exe

C:\Program Files (x86)\Mozilla Firefox\firefox.exe

C:\Program Files (x86)\uTorrent\uTorrent.exe

C:\Program Files (x86)\IncrediMail\bin\IncMail.exe

C:\Program Files (x86)\IncrediMail\bin\ImApp.exe

C:\Program Files (x86)\Macromedia\Dreamweaver MX\Dreamweaver.exe

F:\VegyesNetFruit\prg-felhasznaloi\firewall_virus_spam\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 219.93.178.162:3128

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,Shellnext = http://go.microsoft.com/fwlink/?LinkId=74005

F2 - REG:system.ini: UserInit=userinit

O2 - BHO: (no name) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.6.0_03\bin\ssv.dll

O4 - HKLM\..\Run: [iMJPMIG8.1] "C:\WINDOWS\IME (x86)\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32

O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC

O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files (x86)\Java\jre1.6.0_03\bin\jusched.exe"

O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE

O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE

O4 - HKLM\..\Run: [CtxfiReg] CTXFIREG.exe /FAIL2

O8 - Extra context menu item: E&xportálás a Microsoft Excel programba - res://C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000

O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)

O9 - Extra button: Research (HKLM)

O9 - Extra button: Messenger (HKLM)

O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)

O11 - Options group: [iNTERNATIONAL] International*

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{30567F62-D12F-4D44-A6F4-2084824B2D8E}: NameServer = 84.2.44.1,84.2.46.1

Link to comment
Share on other sites

thx guys, i'm on it... hope it'll resolved soon. :-/

my first thought was ESET, but it didn't cause problem before.

***

edit:

:(( i've ran Process Explorer... but i don't know what should i see in it.. there are no shady processes.. how can i find "which program has grabbed hold of those files" ?

(please help! i feel myself so lamer)

******

edit2:

here is the Process Explorer's savefile:

a text file

******

edit3:

i think, the problem is only with the torents whose contains .exe files... mhmm... i wonder, what program can block these files..?

Link to comment
Share on other sites

Though you can deduce which process has open said files, it is not as simple as click-search.

There are two modes for the lower pane in Process Explorer, DLL mode (Ctrl-D) and Handle mode (Ctrl-H).

You will need to switch to handle mode, and I have found sorting by file flags helps alot.

All files opened by uT for example have -RW-.

What you will need to do, for the specific files you are searching is to start at a likely process and work up or down.. Note you can skip the whole process tree for services... Unless you have some sort of filesystem protection service startup.

Link to comment
Share on other sites

ooh :( i've tried my best, but it's too difficult to me.

so.. i have the handle mode, and sorting by 'file share flags' .. but i can't find any "-RW-" (i don't even know what is it..)

"What you will need to do, for the specific files you are searching is to start at a likely process and work up or down.. Note you can skip the whole process tree for services... Unless you have some sort of filesystem protection service startup."

work up or down.. hmm.. this is not clear to me :-j - where should i click?

what are the "specific files" ?

and the process tree... is this in the upper half in the ProcessExpl. window?

and the "filesystem protection" - is it the NOD32 (eg.) ? - but in this case why this doesn't stop the torrent files (which contains .exe) from public trackers?

here is a picture, that's where i'm now:

uT1.jpg

i know i'm so difficult person, with a lack of skills in this case, but please help me further :)

Link to comment
Share on other sites

You selected the right thing up-top. :)

As far as the lower pane.. you switched to Ctrl-h :D

But I too don't see any flags... Did you sort the other way (flip downward arrow to upward-facing)? :/

Also, I recommended searching ALL processes (to be thorough). But if you don't see uT having the file open for writing... there's a problem there as well. What you will see, especially on "indexing services" or "filesystem protection" is that the process (up top) has LOTS of files open that you are using, for example downloading in uT. This can cause problems if they open it in W (write) mode, which means then uT cannot access it.

Link to comment
Share on other sites

i don't see any flags like -RW- only "---" as you see on the picture... is there a problem? (yes, i know.. but i don't know how is it)

i've examine the processes, but i don"t see -RW- anywhere.

***

okay, i've lost the line... what should i do with what?? :D "indexing services" or "filesystem protection" - i haven't seen these in the ProcExp..

did you mean the explorer.exe's sub-processes??

i've seen only one uTorrent.exe line with purple color in the upper screen, and i don't find the "W" sign (for write mode)..

uhh.. i'm so sad.. and feel so silly :-/

Link to comment
Share on other sites

I don't know why you wouldn't see any files opened, ESPECIALLY by uT.

Here is a logging instance of uT I use for test downloads.

ut186838procexphandlesaw3.th.png

you will notice aside from windows DLLs I have open my read directory "M:\New Folder", my write directory "J:\Download\Done", and the logfile "O:\µTorrent\beta\1\6838.1207.log"

Edit: I notice in the pic there is a folder I presume you use "D:\downloads\torrents"... why it does not show write flags, i am at a loss... It is possible that is a quirk of Vista.

What I meant about the interference programs that do "real-time monitoring" is that in the bottom pane there you would see ITs process, as well as uTs process trying to access the file, rendering uT's ability to write to it useless..

But given you don't see any write flags.. Perhaps you can try double sorting? or sort by "name" descending (downward arrow). That should put utorrent.exe process information first, followed by open files (at least it does that on my opened filesystem)

ut186838procexphandlesnnc4.th.png

Link to comment
Share on other sites

hi im new to the forums...i have had utorrent for a fair while though and had no problems with it...until now :S

last couple of days i reformatted my pc and since then i have been getting the access denied problems too.

i ran that hijackthis as you suggested to other people here are the reuslts:

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 12:39:42 AM, on 13/12/2007

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16574)

Boot mode: Normal

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe

C:\Program Files\Alwil Software\Avast4\ashServ.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\RUNDLL32.EXE

C:\Program Files\Analog Devices\Core\smax4pnp.exe

C:\Program Files\Analog Devices\SoundMAX\Smax4.exe

C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

C:\Program Files\iTunes\iTunesHelper.exe

C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

C:\WINDOWS\system32\nvsvc32.exe

C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe

C:\PROGRA~1\INTERN~2\mum.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe

C:\Program Files\Alwil Software\Avast4\ashWebSv.exe

C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe

C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe

C:\Program Files\iPod\bin\iPodService.exe

C:\Program Files\MSN Messenger\msnmsgr.exe

C:\Program Files\MSN Messenger\usnsvc.exe

C:\Program Files\iTunes\iTunes.exe

C:\Program Files\uTorrent\uTorrent.exe

C:\PROGRA~1\MOZILL~1\FIREFOX.EXE

C:\WINDOWS\system32\svchost.exe

C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.vso-software.fr/affiliate/thankyou.php?p=ConvertXtoDVD

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O4 - HKLM\..\Run: [iMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32

O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC

O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [soundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe

O4 - HKLM\..\Run: [soundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray

O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime

O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"

O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"

O4 - HKCU\..\Run: [internodeUsage] C:\PROGRA~1\INTERN~2\mum.exe

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{F9C872EE-10C1-4A30-9516-412A350B5B01}: NameServer = 192.231.203.132,192.231.203.3

O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe

O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe

O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe

O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe

O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe

O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

--

End of file - 5424 bytes

Any idea from that what my issue might be?

Link to comment
Share on other sites

First I thank you for researching a bit before reporting a problem.

However, as others recently experiencing this problem also have this, could you tell me what this is:

O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe

What version / type of Ahead software are you running.

Generally speaking, ANY indexer which has access to the uT download directory can cause problems. Sure not all do it, but a majority interfere due to applying file permissions settings which essentially "lock out" uT from continued access and therefore an inability to continue to download.

Also, has any of this software been recently installed. I know you said it is a reformat, but did you try uT before installing all of your software?

Link to comment
Share on other sites

dear Jewelisheaven! :-oo i don't understand why my uT has different properties (lack of -RW- and others).. i'll go and set up a temporary folder like you, nad a finished folder, and try to check this again then.

and i have win xp pro x64 - this can be the root of the problem :-S

hmm-hmm.. i'll be back at tomorrow with new results or maybe new questions ;)

good night!

Link to comment
Share on other sites

While I don't use x64 XP I do know it got more testing than the newer Vista x64.

As far as write flags, if the files are being written to but they're not being shown.. I'm assuming it's something to do with x86x64 -> x86 (32-bit) translation... but I have no idea.

As a bruteforce method to the solution can you turn OFF / close process of ALL real-time monitors (anti virus / software firewall / internet protection ) and re-enable them one by one re-trying to start one torrent to see if you can identify which process is causing this.

OH OH!! What version / suite of Nero software are you using. Both the indexer and backup service may indeed be trying to write to the files. So if you could try those processes first... I'd hope any additional features can be turned off in the main Nero configuration screen... So please try with Nero first to see if that's the problem.

Recently (was there an update??) we've had alot of people with problems exhibit the same services in their HJT logs.

Link to comment
Share on other sites

Thanks for the response Jewel and Firon. I have nero7 suite, its the same as i had before the format, infact i havent got any different programs than before.

I have disbaled nero scout and i still got the problems. even after reinstalling utorrent and getting new ports etc.

Im currently uninstalling nero 7 to see if this helps and will post back any results

Cheers

edit: still getting the problem after uninstalling nero

Link to comment
Share on other sites

What about AVAST? Anti virus really REALLY don't like files being written to as they're scanning.

Is it possible prior to the reformat you had a rule to exclude your uT and uT download folders from real time scanning?

Thanks for all the checking. I hope you don't think we look down on all of these services, it's just that ... from a usability standpoint, the more programs you have running, the more possible conflict there can be. And I'm not talking about all programs, but for example there was this guy who made a torrent and started seeding it, then he couldn't make any OTHER seeds since his media player added tags to his files... And that's only one instance that occurred recently.

Link to comment
Share on other sites

Jewelisheaven :DDD !!!!

You are a miracle :)))

on the grounds of your "bruteforce" method;

1. i've finally figured out, that the Comodo firewall was the guilty application

2. i was checking the settings

3. and TA-DAAAM!.. one little checkbox was the problem's source

uT3.jpg

so, THANK YOU very much! :))

i'm so glad and happy :D

it i've got problems with uT in the future, i'll be back trustfully ;)

bye-bye for now!

Link to comment
Share on other sites

ok so despite being determined to get this problem of mine fixed...i decided to download BitTorrent instead of using uTorrent...it works fine without any system changes and all my applications running without any problems...sigh oh wells at least i can d/l again xD

Thanks again for your advice guys, i really appreciate it :)

Link to comment
Share on other sites

Archived

This topic is now archived and is closed to further replies.

×
×
  • Create New...